top | item 45662463

(no title)

roblabla | 4 months ago

You can also use phishing-resistant login/2FA like passkeys/FIDO keys, where it is available (and I'm pretty sure amazon supports it), to minimize the risk of accidentally login into a phishing website while under pressure.

discuss

order

akerl_|4 months ago

If my memory is correct, AWS supports FIDO for web login but not for the API, so you either have to restrict access to FIDO and then use the web UI for everything done as that user, or have a separate non-FIDO MFA device (without FIDO's phishing resistance) for terminal/API interactions.

SoftTalker|4 months ago

They probably support it but how many accounts have not configured it? I'd bet it's a lot.